Red Hat Ceph 14.2.16

CPE Details

Red Hat Ceph 14.2.16
14.2.16
2021-05-24
15h53 +00:00
2021-05-24
17h13 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:ceph:14.2.16:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

ceph

Version

14.2.16

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-27839 2021-05-26 19h25 +00:00 A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
5.4
Medium
CVE-2021-3531 2021-05-17 22h00 +00:00 A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.
5.3
Medium
CVE-2021-3524 2021-05-16 22h00 +00:00 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
6.5
Medium
CVE-2020-25678 2021-01-08 17h59 +00:00 A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
4.4
Medium